Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS.

This issue affects Web Design: through 25082026.
Published: 2026-08-28
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting (XSS)
Action: Patch Update
AI Analysis

Impact

Improper neutralization of user input was discovered in Ceviz Informatics Inc. Web Design, allowing attacker supplied data to be reflected in a browser and executed as malicious JavaScript. The vulnerability can lead to credential theft, session hijacking, or tampering with user interactions with the web application, compromising confidentiality, integrity, and availability of user sessions.

Affected Systems

Ceviz Informatics Inc. Web Design is affected in all releases up to and including 25082026. No other vendors, products, or versions were listed by the CNA.

Risk and Exploitability

The CVSS score of 6.1 indicates a medium severity with potential for moderate damage if exploited. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is through crafted URLs or form input that browsers will reflect and execute. Exploitation requires only that a malicious user entice a victim to visit a malicious link or submit crafted data, making it realistic in phishing or social‑engineering scenarios.

Generated by OpenCVE AI on August 28, 2026 at 16:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Web Design to a version later than 25082026 once a fix is released.
  • If no patch is available immediately, implement server‑side output encoding or sanitization for all reflected user input parameters.
  • Deploy a web application firewall to detect and block suspicious script injections on incoming HTTP requests.

Generated by OpenCVE AI on August 28, 2026 at 16:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Ceviz Informatics Inc.
Ceviz Informatics Inc. web Design
Vendors & Products Ceviz Informatics Inc.
Ceviz Informatics Inc. web Design

Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS. This issue affects Web Design: through 25082026.
Title Reflected XSS in Ceviz Informatics's Web Design
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Ceviz Informatics Inc. Web Design
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-28T18:22:59.845Z

Reserved: 2026-04-09T07:27:29.654Z

Link: CVE-2026-5953

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-28T16:18:19.797

Modified: 2026-08-31T13:08:21.090

Link: CVE-2026-5953

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:31:55Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')